anysearch
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection via the
extractcommand. - Ingestion points: The
extractsubcommand in all CLI scripts (scripts/anysearch_cli.py,scripts/anysearch_cli.js,scripts/anysearch_cli.sh,scripts/anysearch_cli.ps1) fetches and returns external web content to the agent. - Boundary markers: The
SKILL.mdfile includes a specific warning for the agent to treat page content as untrusted data and not to follow embedded instructions. - Capability inventory: The skill is capable of network operations (API search and extraction) and file writing (updating
.envandruntime.conf). - Sanitization: Content is returned to the agent as raw Markdown without specific filtering or sanitization of potential injection strings.
- [COMMAND_EXECUTION]: The
scripts/test_cli.pyscript usessubprocess.runto execute the skill's CLI tools for contract testing, which involves spawning subprocesses to verify script behavior. - [DATA_EXFILTRATION]: By design, the skill transmits search queries, URLs, and API keys to the vendor's API at
api.anysearch.comduring normal operation.
Audit Metadata